Author
Abdulaziz Alzamil
Founder & CEO, Fyntralink
Abdulaziz Alzamil is the founder and CEO of Fyntralink and writes the Fyntralink blog: analysis of vulnerabilities and cyber threats and what they mean for Saudi organisations, readings of regulatory frameworks such as the NCA Essential Cybersecurity Controls and the Personal Data Protection Law, and pieces on AI and software engineering.
400 articles
MuddyWater's False-Flag Playbook: Iranian APT Hides Espionage Behind Chaos Ransomware
Iranian APT MuddyWater deployed Chaos ransomware as a decoy while conducting espionage via Microsoft Teams social engineering. Saudi CISOs must rethink their IR playbooks.
Breaches & Data LeaksShinyHunters' 2026 Breach Spree: How One Group Compromised Billions of Records Across Six Sectors
ShinyHunters breached the EU Commission, Medtronic, Rockstar Games, and 8,809 universities in five months — all through OAuth misconfigurations and supply chain trust. Here's what Saudi financial CISOs must do now.
VulnerabilitiesFirst AI-Generated Zero-Day Exploit Caught in the Wild: What Saudi Financial CISOs Must Know
Google confirms the first AI-generated zero-day exploit used by criminal hackers — a 2FA bypass built by an LLM. What this means for Saudi financial institutions and how CISOs should respond.
Compliance & RegulationNCA NCNICC-1:2025: Every Saudi Private Company Now Faces Mandatory Cybersecurity Controls
NCA's NCNICC-1:2025 makes cybersecurity controls mandatory for all Saudi private companies. Learn the 65 controls, Category A vs. B requirements, and how to achieve compliance alongside SAMA CSCC.
VulnerabilitiesWindows MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Systems — PoC Is Public
A weaponized PoC exploit called MiniPlasma grants SYSTEM privileges on fully patched Windows 11 systems by exploiting a six-year-old flaw in the Cloud Filter driver. Here's what Saudi financial institutions must do now.
VulnerabilitiesCVE-2026-41103: Microsoft SSO Plugin Flaw Gives Attackers Admin Access to Your Jira and Confluence
A CVSS 9.1 flaw in Microsoft's SSO Plugin lets unauthenticated attackers forge SAML responses and gain admin access to Jira and Confluence—exposing compliance data, security findings, and internal documentation across SAMA-regulated institutions.
VulnerabilitiesCVE-2026-42897: Exchange OWA Zero-Day Turns a Single Email into Full Browser Hijack
Microsoft confirms active exploitation of CVE-2026-42897, a stored XSS in Exchange OWA that hijacks authenticated sessions via a single crafted email. CISA KEV-listed with a May 29 deadline—Saudi financial institutions must patch within 48 hours to meet SAMA CSCC requirements.
Cloud & IdentityTycoon2FA Rebounds: Device-Code Phishing Bypasses MFA to Hijack Microsoft 365 Accounts
The Tycoon2FA phishing-as-a-service kit has rebounded after a March takedown, now weaponizing OAuth device-code flows to steal Microsoft 365 tokens — rendering traditional MFA useless. Here's what Saudi CISOs need to know.
Software EngineeringGrafana GitHub Token Breach: How a CI/CD Misconfiguration Exposed the Codebase Behind Your SOC Dashboards
A single misconfigured GitHub Action let attackers steal Grafana's entire codebase. For Saudi financial institutions relying on Grafana for SOC dashboards, the breach raises urgent questions about CI/CD pipeline security and open-source supply chain risk.
Supply Chain & Third PartyMini Shai-Hulud Worm: How One npm Install Compromised 160+ Packages and Stole CI/CD Secrets
A self-propagating worm dubbed Mini Shai-Hulud hijacked 160+ npm and PyPI packages — including TanStack and Mistral AI — turning every compromised developer into a new infection vector. Here's what your DevSecOps team needs to act on immediately.
VulnerabilitiesPwn2Own Berlin 2026: 47 Zero-Days in Enterprise Tech Expose What Scanners Miss
47 zero-days across Exchange, SharePoint, VMware ESXi, and AI platforms — $1.3M in bounties at Pwn2Own Berlin 2026. What the results mean for Saudi financial institutions and their 90-day patch window.
VulnerabilitiesMicrosoft May 2026 Patch Tuesday: Azure DevOps CVSS 10.0 and Netlogon RCE Demand Immediate Action
Microsoft patched 118 vulnerabilities in May 2026, including CVE-2026-42826 — a perfect CVSS 10.0 Azure DevOps information disclosure flaw exploitable without authentication. Here's what Saudi financial institutions must patch first.